Legal
SweQR Privacy Policy
How SweQR processes personal data
Effective date: 29 August 2026 · Last updated: 29 August 2026
1. About this Policy
This Privacy Policy explains how SweQR processes personal data when you visit sweqr.com, use the public Design Studio, create or use an account, create or manage a Dynamic QR identity, scan a SweQR-managed Dynamic QR, contact us, submit an abuse report, or otherwise interact with the Service.
The data controller is Thomas Johansson, a sole trader established in Sweden and trading as SweQR, with public business address Mejramvägen 16, 611 45 Nyköping, Sweden (“SweQR”, “we”, “us” or “our”). Privacy contact: hello@sweqr.com.
This Policy does not govern a third-party destination reached through a QR code. The destination operator is responsible for its own processing. Paddle independently processes buyer and payment information as Merchant of Record under Paddle’s own privacy notice.
2. Personal data we process
2.1. Account and profile data
We process information such as your email address, account identifier, authentication and verification status, selected language, plan and entitlement information, consent records, account roles, security settings and account creation or update timestamps. If you use third-party sign-in, we receive the identifiers and profile information that provider makes available for authentication.
2.2. Static designs and managed Dynamic QR data
The public Design Studio generates a true Static QR payload and artwork in the user’s browser. The final URL or other content is encoded directly in the artwork. Creating a true Static QR does not create a managed QR record, short code, redirect mapping or account-owned QR identity. Ordinary web-security and request logs may still be created when the person visits the Design Studio, but SweQR does not receive a later scan merely because the artwork was created there.
For managed Dynamic QR codes, SweQR processes the permanent short code and assigned redirect hostname, current destination, QR name or note, design assets, creation and update records, account ownership, Custom Domain information, validation results, safety and lifecycle status, and applicable entitlement and capacity information. A destination URL or uploaded asset may contain personal data if you place it there. Do not submit sensitive personal data unless it is lawful and necessary.
2.3. Static scans and managed Dynamic redirects
When somebody scans a true Static QR, the scanner’s device reads the final encoded URL or other content directly. No request is made to SweQR merely because SweQR’s Design Studio generated the artwork. SweQR therefore receives no redirect request, creates no SweQR scan telemetry and provides no Dynamic analytics for that scan. The encoded destination, the scanner’s network provider and the scanner’s device may process data under their own rules.
When somebody requests a SweQR-managed Dynamic link, SweQR and its edge provider process the requested hostname and short code, date and time, response and safety outcome, and limited browser, device, referrer-host, country and diagnostic information where available. Durable analytics are daily request aggregates and are approximate; they are not verified counts of unique people. This data is used to deliver the redirect, protect scanners and infrastructure, diagnose incidents and provide plan-eligible analytics.
Network infrastructure necessarily processes the scanner’s IP address to route and secure the request. The SweQR application does not intentionally write the raw scanner IP address to its Postgres scan-analytics tables or structured resolver-event payloads. Abuse controls derive a keyed, day-rotated pseudonymous source value. Reusable source-control tables are configured for 48-hour retention, but the reporter hash stored with a public abuse report remains with that report for its 180-day retention window. Pseudonymisation does not by itself make the value anonymous.
Those provider logs are retained under the enabled service configuration and applicable provider agreement. SweQR limits access and keeps such data only for service delivery, security, incident investigation and legal obligations, with periodic review of whether continued retention is necessary.
SweQR does not require a scanner to create an account merely to follow an ordinary Dynamic redirect.
2.4. Billing and transaction data
Paddle acts as authorised reseller and Merchant of Record for paid transactions and independently collects buyer identity, payment method, billing address, tax and transaction information. SweQR receives limited buyer, order, subscription, entitlement, refund, dispute and fraud-related information needed to deliver the Service, manage account access, reconcile payments and provide product support. SweQR does not receive or store full payment-card numbers.
2.5. Support, abuse and communications data
We process messages, attachments, contact details, support history, abuse notices, evidence, affected URLs or QR identities, enforcement decisions, statements of reasons and related communications. Please avoid sending unnecessary sensitive information.
2.6. Security and administration data
Authenticated security and provider-generated records are retained only for as long as needed to secure accounts, investigate incidents, meet legal obligations and defend claims. The period depends on the record and provider configuration; access is restricted and continued necessity is reviewed.
3. Where the data comes from
- directly from you when you register, configure the Service, upload content, buy a plan, contact support or submit a report;
- automatically from browsers, devices, redirects, security systems and service logs;
- from Paddle and other providers involved in authentication, payment, delivery, security and communications;
- from public or specialist sources used to assess destination safety, such as domain-registration, reputation, threat and abuse information; and
- from third parties who submit an abuse notice, legal request or security report.
4. Why we process data and our legal bases
4.1. Contract
We process information necessary to provide a requested Design Studio session and, for account holders, to create and administer the account, issue and operate managed Dynamic identities, maintain destinations, provide Custom Domain and team functions, authenticate users, provide support and apply plan entitlements. A later scan of a true Static QR is not processed by SweQR under the customer’s account contract.
4.2. Legitimate interests
We process limited data where necessary for our legitimate interests in securing accounts and infrastructure; detecting phishing, fraud and abuse; protecting scanners and redirect-domain reputation; maintaining the permanent non-reuse ledger for issued identities; diagnosing failures; defending legal claims; improving reliability; and understanding aggregated use of the Service. We assess these interests against affected individuals’ rights and use data minimisation, access controls, short log-retention periods and human review where appropriate.
The permanent issuance ledger is retained under legitimate interest specifically for its role after an individual customer relationship ends or a code is deactivated. Ensuring that a short code and redirect hostname are never reassigned protects every SweQR customer and scanner, not only the account that originally created the code. While an account is active, the same data is also processed under section 4.1 (Contract) to operate the issued codes.
4.3. Legal obligations
We process and retain data where necessary to comply with accounting, tax, consumer, sanctions, law-enforcement, Digital Services Act, data-protection and other legal obligations, and to respond to valid orders or requests.
4.4. Consent
We rely on consent for non-essential cookies, direct electronic marketing and other processing where consent is legally required. You may withdraw consent at any time without affecting processing already carried out lawfully.
4.5. Vital interests and legal claims
In exceptional cases, we may process data to protect a person’s vital interests or to establish, exercise or defend legal claims, as permitted by law.
5. Redirect safety and automated processing
Google may process lookup data under the applicable Google Cloud service terms and privacy documentation; SweQR limits the submitted data to what is necessary for the destination-safety check.
An unverified report or heuristic signal is suspicion rather than a confirmed malicious verdict and ordinarily results in review, an interstitial or another reversible measure. A confirmed malicious verdict from an approved trusted provider may produce an immediate automated block. The check concerns destination safety rather than personal characteristics of an individual. An automated confirmed block is not automatically reversed; reversal requires an authorised human decision.
A true Static QR does not pass through SweQR when later scanned, so SweQR cannot continuously inspect or block its encoded destination after download.
A person affected by an automated safety restriction may request human review through hello@sweqr.com. Decision reasons are recorded internally, and a legally required customer-facing notice may be sent manually by email.
7. International data transfers
SweQR is established in Sweden. Some providers may process personal data outside Sweden or the European Economic Area. A restricted international transfer is made only where a lawful mechanism is available, such as an applicable adequacy decision, the European Commission’s Standard Contractual Clauses with supplementary safeguards where required, or another mechanism permitted by data-protection law. You may contact hello@sweqr.com for information about safeguards relevant to a particular transfer.
8. How long we retain data
We retain personal data only for as long as necessary for the stated purpose, subject to legal holds, security investigations, active disputes, accounting obligations and applicable infrastructure backup cycles. The following periods are supported by current application configuration and purge-job evidence:
- Static QR scans: no SweQR redirect record or scan telemetry is created merely because a true Static QR made in the Design Studio is scanned.
- Reusable pseudonymous source-control tables: 48 hours. The pseudonymous reporter hash held with a public abuse report follows the report’s 180-day period rather than the 48-hour source-table period.
- Guardrail/rate-control event records: 3 days. Product-event records, which may be linked to an account and may contain limited event properties, and terminal transactional-email outbox records: 90 days. Product-event properties must remain minimised to the documented event purpose.
- Safety-chain observations, where generated: 90 days. The chain-observation feature is disabled in the current runtime; the period applies to any records that exist.
- Abuse signals: 90 days. Public abuse-report records, including optional details and reporter hash: 180 days. Resolved abuse-review records: 365 days after resolution. Unresolved matters remain until resolved; a legal hold or active proceeding may require longer.
- Aggregated managed Dynamic scan statistics and facets: up to 1,130 days. These tables contain daily counts and limited facets and do not contain raw scanner IP.
- Permanent issued-identity ledger: the issued short code, redirect hostname, issuance/account reference and non-reuse status are retained permanently so no issued identity can be assigned to somebody else.
- Deactivated issued-code mapping after completed account deletion: the former destination is replaced with a neutral non-resolving value, and destination and host values in the destination-change history are redacted at completion. The history rows remain with actor, reason and timestamps so authorised actions remain auditable. The permanent code, redirect hostname and pseudonymous internal account reference remain for referential integrity and identity-reservation proof.
- Account/authentication data: retained while required for an active account. On completed deletion the account closes and memberships are removed. The workflow attempts to delete an authentication identity only when it is not required by another active SweQR account, remove saved account designs and short-lived request-source records, and clear customer-authored QR notes. The completion result and any failed cleanup must be reviewed rather than treating the request alone as proof of erasure.
- Support, administrative audit, security, safety, destination-history and SweQR billing records: retained for the period reasonably necessary to resolve the matter, protect the Service, demonstrate authorised actions, meet legal obligations or establish, exercise or defend claims. Active investigations, disputes and legal holds may require longer retention.
- Transaction and accounting records: retained for the period required by applicable accounting and tax law. Paddle retains its own transaction records under its privacy notice. Essential browser storage follows the session or purpose for which it is set. Backups are overwritten or deleted under the applicable infrastructure backup cycle and may remain inaccessible to ordinary operations until that cycle completes.
A request for erasure does not require deletion of data that SweQR must or may lawfully retain, but retained data must be limited to and protected for the applicable purpose.
9. Account deletion and issued QR identities
Account deletion is a staged, human-reviewed process available to the account owner. The owner chooses whether all issued Dynamic QR codes should keep resolving or be deactivated. The current flow does not support a different choice for each code.
The deletion process does not automatically cancel an active Paddle subscription. Completion is blocked until the subscription has been cancelled through Billing or Paddle and the resulting billing state has been reconciled.
On completion, the account closes and memberships/invitations are removed or revoked. The workflow attempts to clear QR notes, remove saved designs and short-lived account request-source records, and delete an authentication identity only where it is not still needed for another active account. The completion record must be checked and failed cleanup followed up. If deactivation was selected, issued codes stop redirecting; otherwise they continue under their existing destination, safety and lifecycle state.
In both cases, issued-code rows retain the permanent short code, redirect hostname, a pseudonymous internal account reference and necessary safety/lifecycle state. If deactivation was selected, the former destination is replaced with a neutral non-resolving value and destination and host values in the destination-change history are redacted; if keep-active was selected, the last permitted destination remains because the code continues resolving. Custom Domain records carrying issued identities are retained. Support cases and billing, security, safety and audit history may remain.
These retained elements are access-restricted and remain subject to necessity review, legal obligations and the rights described below.
10. Your data-protection rights
Depending on applicable law, you may have the right to:
- receive information about our processing and obtain access to your personal data;
- correct inaccurate or incomplete data;
- request erasure or restriction of processing;
- object to processing based on legitimate interests, including direct marketing;
- withdraw consent at any time;
- receive data you provided in a structured, commonly used and machine-readable format where the right to portability applies; and
- lodge a complaint with a data-protection authority.
To exercise a right, contact hello@sweqr.com. We may need to verify your identity and may ask for information needed to locate the relevant data. We normally respond within one month. Where a request is complex or we receive a high number of requests, this may be extended by up to two further months; if so, we will tell you within the first month and explain the reason for the delay. Rights are not absolute; if we cannot comply fully, we will explain the applicable reason where permitted.
If you are in Sweden, you may complain to Integritetsskyddsmyndigheten (IMY), www.imy.se. You may also contact the supervisory authority where you live, work or believe an infringement occurred.
12. Security
We use technical and organisational measures intended to protect personal data, including access controls, authentication protections, encryption in transit, audit logging, role separation, safety controls, backups and monitoring. No system is completely secure. Report a suspected security incident to security@sweqr.com. General privacy requests remain directed to hello@sweqr.com.
13. Children
SweQR accounts, paid plans and managed Dynamic QR functions are intended only for people who are at least 18 years old. A person under 18 should use the public Design Studio only with the involvement of a parent or legal guardian where required by applicable law.
14. Changes to this Policy
We may update this Policy to reflect changes in law, providers, features or processing. We will publish the updated version and revise the “Last updated” date. Where a change materially affects individuals, we will provide additional notice where required.
15. Contact
Data controller: Thomas Johansson, sole trader trading as SweQR
Public business address: Mejramvägen 16, 611 45 Nyköping, Sweden
Privacy email: hello@sweqr.com
Security reports: security@sweqr.com
SweQR has not appointed a formal Data Protection Officer. Privacy enquiries are handled through hello@sweqr.com.